How to Fix Microsoft 365 Error AADSTS501209 Expired JWT Signing Key
Question details
The user is encountering authentication error code AADSTS501209, indicating that a JSON Web Token (JWT) signature was validated using an expired key.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to sign in or authenticate an application integrated with Microsoft Entra ID.
- Observed behavior
- The authentication process fails, returning error AADSTS501209 because the application's configuration uses expired credentials or signing keys.
Ensure you have Microsoft Entra ID (formerly Azure AD) administrator privileges or contact your IT administrator, as resolving this requires accessing enterprise application configurations in the Azure portal.
Update Application Credentials in Microsoft Entra ID
Replace the expired certificates, client secrets, or signing keys for the affected application registration.
This error originates from an application registration or authentication configuration rather than a local Microsoft Office installation issue.
Log in to the Microsoft Entra admin center or Azure portal using an administrator account.
Navigate to 'Identity' in the left sidebar, expand 'Applications', click on 'App registrations', and select the application causing the error.
Click on 'Certificates & secrets' in the application's left menu. Review the current client secrets and certificates, and delete any that have expired.
Create a new client secret or upload a valid certificate. Update the external application's configuration code to use these new credentials and test the sign-in again.

Create a Microsoft Support Request
Contact Microsoft Support if the error occurs with a core Microsoft service or cannot be resolved by the tenant administrator.
Switch to WPS Office for a Hassle-Free Experience
Tired of dealing with complex Microsoft 365 authentication errors and subscription issues? WPS Office offers a free, lightweight, and highly compatible alternative for your document needs without the hassle of Azure AD configurations.
- 1. Download WPS Office: Visit the official WPS website and click 'Download WPS Office Free'.
- 2. Install the Software: Run the downloaded installer and follow the on-screen instructions to complete the setup.
- 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Office documents without any complex sign-in requirements.

Frequently Asked Questions
What does error AADSTS501209 mean?
It indicates that an application attempting to authenticate with Microsoft Entra ID is using a JSON Web Token (JWT) signature that was validated with an expired key.
Can a standard user fix the AADSTS501209 error?
Usually, no. This error requires an IT administrator or a Microsoft Entra ID administrator to update the application's credentials, client secrets, or signing keys in the Azure portal.
Does reinstalling Microsoft Office fix AADSTS501209?
No. This is an authentication and application configuration issue on the server side, not a problem with the local Office installation. Reinstalling desktop applications will not resolve it.
Where do I find the correlation ID for my support ticket?
The correlation ID and timestamp are usually displayed directly on the error screen when the AADSTS501209 authentication failure occurs. You can copy these details directly from the prompt.




